Threat Database Trojans Trojan.Injector.WC

Trojan.Injector.WC

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 62
First Seen: January 3, 2013
Last Seen: April 16, 2026
OS(es) Affected: Windows

The detection of Trojan.Injector.WC on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malicious software that can cause harm to your computer or steal sensitive information. In this report, we will provide an overview of what Trojan.Injector.WC is, how it operates, the symptoms of infection, and most importantly, the steps you can take to remove it from your system.

What Is Trojan.Injector.WC?

Trojan.Injector.WC is a type of malware that can infect your computer without your knowledge or consent. The name itself suggests that it is a Trojan-type threat, but the specifics of its operation and goals can vary. Trojans are often designed to allow unauthorized access to your computer, steal sensitive information, or disrupt the normal functioning of your system. They can be spread through various means, including infected software downloads, malicious email attachments, or exploited vulnerabilities in your system or applications.

How Trojan.Injector.WC Operates

Once Trojan.Injector.WC infects your computer, it can operate in various ways to achieve its malicious goals. It might create backdoors for remote access, allowing hackers to control your computer, steal data, or use your system for malicious activities. It could also install additional malware, modify system settings, or disrupt the performance of your computer. Understanding the exact operation of Trojan.Injector.WC requires detailed analysis, but the general approach to removing such threats involves a combination of system cleaning, software updates, and enhancing security measures.

Symptoms of Infection

The symptoms of a Trojan.Injector.WC infection can vary, but common indicators include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs running in the background. You might also notice changes in your browser settings, unexpected pop-ups, or suspicious network activity. In some cases, the infection might not display obvious symptoms, making it crucial to regularly scan your system for malware using reputable security software.

How to Remove Trojan.Injector.WC

Removing Trojan.Injector.WC from your system requires a systematic approach to ensure all components of the malware are eliminated. Here are the steps to follow:

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall any suspicious programs that were installed without your knowledge or consent, as they might be related to the Trojan.Injector.WC infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan to ensure that all malware components have been removed and your system is clean.

Conclusion

The removal of Trojan.Injector.WC is crucial to protect your computer and sensitive information from potential harm. By following the steps outlined in this report and maintaining good security practices, such as regularly updating your software, using strong antivirus protection, and being cautious with email attachments and downloads, you can significantly reduce the risk of future infections. Remember, staying informed and proactive is key to safeguarding your digital security in today's evolving threat landscape.

Analysis Report

General information

Family Name: Trojan.Injector.WC
Signature status: No Signature

Known Samples

MD5: e28309e765979c9807e9c7a92ae1153b
SHA1: ef53e17381a55157bced3d61ad20406d36b97d53
SHA256: 627E28371A5405B71B249F0021FB3A722A7F82A637548DDF169839902A2DB5C4
File Size: 5.23 MB, 5232734 bytes
MD5: 10d81b8cd339b53c6750c250f1a5ac65
SHA1: 6b0ef47abcee1ed42e610f71d1741536deda9d95
SHA256: 9D51B52B79E2404C0D42FB91E36D1DBC2F9D7F7F68B7922DCBBB0AAC46302455
File Size: 7.11 MB, 7109632 bytes
MD5: 86da88948b8b13458030e97850401699
SHA1: 4901cc8cc0292e323c8a760dacda489ea8297fd4
SHA256: 1B5CD47A1ACA9FC4EF462A4F617C301AF0050862DDF0563E01C90DB38C9A667B
File Size: 1.49 MB, 1491456 bytes
MD5: 365329e9756ea6f0f28524c8ca7db07a
SHA1: 3548132e55a59c621460379d17c36794ec13226e
SHA256: AD0FE52172AF9056BE2E0E242825AC8C4FCACA2C22BF98E56DF6E045ECC74FBA
File Size: 7.12 MB, 7115264 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • big overlay
  • No Version Info
  • x64

Block Information

Total Blocks: 53,904
Potentially Malicious Blocks: 256
Whitelisted Blocks: 47,331
Unknown Blocks: 6,317

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 x ? 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? 0 0 ? 0 0 ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 x ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? 0 ? ? x 0 ? 0 ? ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? 0 0 0 ? 0 x ? 0 0 x 0 0 0 0 0 0 ? ? 0 0 ? ? 0 ? ? 0 0 0 ? 0 x ? 0 0 x 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 x ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 x 0 x x ? ? 0 x ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 x 0 x x ? ? ? 0 0 0 0 0 ? 0 ? ? 0 ? ? 0 ? ? 0 ? 0 ? ? 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? 0 ? ? ? 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? 0 0 0 0 x 0 ? 0 x ? 0 x ? 0 x ? ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 0 ? 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? 0 ? ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LOFB

Files Modified

File Attributes
c:\users\user\downloads\trackingservice.000.trc Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreatePen
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiDrawStream
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW

119 additional items are not displayed above.

Other Suspicious
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock
  • gethostbyname
  • gethostname
Keyboard Access
  • GetKeyState

Trending

Most Viewed

Loading...